The Point: Approximately 11,000 German companies have apparently not fulfilled their NIS2 reporting obligation and risk substantial fines.
Based on an analysis of registration data, around 11,000 German companies are missing the required NIS2 notification. Fines of up to €500,000 threaten those who do not fulfill their reporting obligation.
Based on an analysis of registration data, it appears that approximately 11,000 companies in Germany have not complied with the reporting obligation under the NIS2 Directive. The European Directive on Network and Information Security (NIS2) requires that critical infrastructures and other organizations disclose their cyber security structures to the authorities.
For companies that do not comply with this reporting obligation, substantial fines of up to €500,000 are threatened. This represents a significant financial risk for many medium-sized and larger companies. The penalty is intended to enforce compliance with the reporting obligation and close gaps in the registered cyber security landscape.
This creates a dual responsibility for CISOs and security officers: on the one hand, they must ensure that their organizations meet the technical requirements of the NIS2 Directive; on the other hand, timely and correct registration with the responsible authorities is required. Identification of affected companies by the authorities could lead to systematic inspections.
Source: news.google.com · Published 18 July 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.